Compliance

DORA

The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector.

The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector. It has applied since 17 January 2025 to banks, insurance companies, investment firms, and many other financial entities in the EU.

How it works

DORA regulates five areas: ICT risk management, incident handling and reporting, digital resilience testing, third-party ICT risks, and information sharing. Major ICT incidents must be reported in several stages. The initial notification is due within 4 hours of classification, and at the latest 24 hours after discovery.

An interim report and a final report follow this notification. Financial entities designated by the competent authority must conduct TLPT at least every three years.

For example, a Swiss-based asset manager has a subsidiary in Luxembourg. DORA applies to this subsidiary. If an attack on the customer portal is detected, the subsidiary must classify and report the incident on time. This is only possible if detection and classification work around the clock.

What to look out for

  • Check which companies within the group fall under DORA.
  • Define incident classification criteria before an incident occurs.
  • Update contracts with ICT service providers to include DORA requirements.
  • Maintain a register of all third-party ICT providers.
  • Practise the reporting process with a tabletop exercise.

Switzerland and regulation

DORA does not apply directly in Switzerland. Swiss institutions are affected if they have subsidiaries in the EU or supply ICT services to EU financial entities. FINMA Circular 2023/1 applies to Swiss banks and securities firms. All supervised institutions must also report cyberattacks to FINMA: initial report within 24 hours of discovery, full report within 72 hours.

Typical mistakes

Many institutions focus on documentation and neglect operations. However, the reporting deadlines can only be met with 24/7 monitoring. Another mistake is service provider contracts without clear obligations for incident support.

How we implement it

Our SOC detects and assesses incidents 24/7, providing the details for classification and reporting. The report itself remains the responsibility of the institution.

How ANOMAL implements this